Home/Training/Certified DevSecOps Engineer

Programme Detail

Certified DevSecOps Engineer

The Certified DevSecOps Engineer programme teaches teams to embed security into planning, coding, building, testing, deployment, and operations. It combines secure...

DevSecOpsRegistration Open

Programme overview

The Certified DevSecOps Engineer programme teaches teams to embed security into planning, coding, building, testing, deployment, and operations. It combines secure development, threat modelling, automation, CI/CD controls, cloud-native security, monitoring, and governance. Participants will apply DevSecOps practices across requirements, code, dependencies, pipelines, infrastructure, containers, cloud deployment, monitoring, and continual improvement.

Programmes can be delivered via

HRD Corp Claimable
Yayasan Peneraju aligned
EC-Council

At a glance

Course code
EC-012
Provider
EC-Council
Category
DevSecOps
Status
Registration Open
Duration
3 days
Price
RM 4,700

What participants should gain

  • Integrate security throughout the DevOps lifecycle
  • Automate code, dependency, infrastructure, and container security checks
  • Apply secure coding, threat modelling, and secrets management
  • Protect CI/CD pipelines and cloud-native environments
  • Establish DevSecOps monitoring, governance, and improvement metrics

Participant readiness

  • Experience in software development, DevOps, cloud, or cybersecurity is recommended
  • Basic understanding of CI/CD and source control
  • Familiarity with containers or cloud platforms is beneficial

Who this course is for

  • Developers, DevOps engineers, security engineers, testers, architects, and platform teams
  • Professionals securing software delivery pipelines and cloud-native environments
  • Teams adopting secure automation across development and operations

How the course is delivered

This programme will be conducted through interactive lectures, pipeline demonstrations, secure-development workshops, guided tool exercises, configuration reviews, group discussions, and a practical DevSecOps activity.

This programme will be conducted through interactive lectures, pipeline demonstrations, secure-development workshops, guided tool exercises, configuration reviews, group discussions, and a practical DevSecOps activity | By enquiry

Course outline

Module and topic breakdown

Module 1: DevSecOps Fundamentals and Culture

DevSecOps principles, culture, shared responsibility, collaboration, and automation

Module 2: Secure Software Development Lifecycle

Planning, requirements, design, development, testing, release, operation, and retirement stages

Module 3: Threat Modeling and Security Requirements

Deriving security requirements from business, data, threat, regulatory, and architectural needs

Module 4: Secure Coding and Code Review

Secure coding standards, defensive programming, input handling, output encoding, and safe APIs

Module 5: Source Control, Secrets, and Supply Chain Security

Repository structure, branching, merge controls, reviews, protected branches, and signed changes

Module 6: CI/CD Pipeline Security

Assets, threat scenarios, vulnerabilities, and attack surfaces addressed by CI/CD Pipeline Security

Module 7: SAST, DAST, SCA, and Automated Testing

Static application security testing and code-quality analysis within development pipelines

Module 8: Infrastructure as Code Security

Declarative infrastructure, templates, modules, state, variables, providers, and reusable components

Module 9: Container and Kubernetes Security

Kubernetes architecture, API server, nodes, workloads, namespaces, services, and controllers

Module 10: Cloud-Native Security and Identity

Assets, threat scenarios, vulnerabilities, and attack surfaces addressed by Cloud-Native Security and Identity

Module 11: Monitoring, Incident Response, and Feedback

Preparation, detection, analysis, containment, eradication, recovery, and lessons learned

Module 12: Governance, Metrics, and DevSecOps Maturity

Governance structures, policies, decision rights, accountability, and oversight committees

Assessment and completion

  • Continuous knowledge checks and facilitator feedback throughout the programme
  • Completion of guided exercises, scenarios, labs, or case-study activities applicable to the course
  • Final review or practical activity to confirm understanding of the stated course objectives
  • Official EC-Council examination and certification requirements depend on the selected training package and current exam version

Availability

This programme has a public intake path. Use the enquiry form below to confirm the next available session or a private cohort.

Programme enquiry

Discuss pricing, delivery, or corporate customisation

Use this form to confirm availability, request pricing clarification, or discuss a private cohort for your organisation.